Blog

CISA confirma el problema detrás del efecto Mythos: más vulnerabilidades, menos tiempo para remediarlas

CISA advierte de que la Inteligencia Artificial está acelerando el descubrimiento de vulnerabilidades y de que el CVSS ya no es suficiente para decidir qué corregir primero. La respuesta pasa por priorizar según exposición, explotación real e impacto.

CISA confirms the problem behind the Mythos effect: more vulnerabilities, less time to remediate them

CISA warns that artificial intelligence is accelerating vulnerability discovery and that CVSS is no longer enough to decide what to fix first. The answer is to prioritize by exposure, real-world exploitation, and impact.

Hace unos días publicábamos en vulloop el artículo «El efecto Mythos: vulnerabilidades descubiertas a velocidad de IA, remediadas a velocidad humana».

La tesis era sencilla: la Inteligencia Artificial puede empezar a encontrar vulnerabilidades mucho más rápido de lo que las organizaciones son capaces de analizarlas, priorizarlas y remediarlas.

La consecuencia es importante. Si el descubrimiento de vulnerabilidades empieza a producirse a escala de máquina mientras que parchear un servidor, probar una nueva versión, aprobar un cambio o coordinar una ventana de mantenimiento continúa dependiendo de procesos humanos, el problema de la gestión de vulnerabilidades cambia radicalmente.

Ya no se trata únicamente de encontrar vulnerabilidades. Se trata de decidir cuáles debemos corregir primero.

Ahora CISA acaba de aportar un argumento especialmente relevante para esta tesis. En su nueva CISA Vulnerability Review, basada en datos de los ejercicios fiscales 2024 y 2025, la Agencia de Ciberseguridad y Seguridad de las Infraestructuras de Estados Unidos analiza qué vulnerabilidades están generando riesgo real, cómo están siendo explotadas y, especialmente, cómo deberían priorizarse.

Una de sus conclusiones es especialmente significativa: «el descubrimiento de vulnerabilidades mediante IA está incrementando rápidamente el volumen de vulnerabilidades divulgadas, lo que exige una priorización mucho más estricta del parcheado».

CISA coincide con el cambio provocado por la IA

Uno de los aspectos más interesantes del informe es cómo CISA posiciona sus propios datos. La agencia explica que publica esta revisión para establecer una línea base del panorama de vulnerabilidades anterior a la generalización del descubrimiento de vulnerabilidades mediante IA.

No está afirmando que todos los nuevos CVE sean consecuencia de la Inteligencia Artificial. Tampoco que exista una relación causal directa entre un modelo concreto y el incremento actual de vulnerabilidades. Pero sí está reconociendo un cambio estructural: la IA está modificando la escala a la que pueden descubrirse vulnerabilidades.

Es precisamente lo que denominamos en nuestro artículo anterior el efecto Mythos. Y CISA añade la otra parte de la ecuación: los ciberdelincuentes también están utilizando cada vez más IA para automatizar las etapas necesarias para explotar vulnerabilidades.

El descubrimiento se acelera; la capacidad de remediar servicios en producción, no.

CISA: el CVSS ya no es suficiente

Durante años, una parte importante de la gestión de vulnerabilidades se ha basado en una lógica relativamente sencilla: Crítica → Alta → Media → Baja.

El problema es que esa clasificación responde fundamentalmente a una pregunta: ¿cuál es la severidad técnica de esta vulnerabilidad? Pero no necesariamente responde a la pregunta que realmente importa a una organización: ¿cuál debo corregir primero?

CISA es especialmente clara en este punto. Según el informe, utilizar el CVSS como principal métrica de decisión resulta insuficiente porque el CVSS refleja severidad teórica, no necesariamente impacto en el mundo real.

Menor prioridad operativa CVSS 9.8
  • Sin explotación conocida
  • Servidor interno y aislado
  • Protegido por varios controles de red

Puede planificarse

Prioridad máxima CVSS 7.8
  • En el catálogo KEV: explotación activa
  • Expuesta directamente a Internet
  • Explotación fácilmente automatizable
  • Permite control de un sistema crítico

Remediación inmediata

El CVSS sigue siendo información relevante, pero deja de ser la decisión.

Las preguntas que CISA propone hacer

Para priorizar vulnerabilidades, CISA propone centrar la decisión en un conjunto reducido de variables.

  • Exposición del activo. ¿Está el activo vulnerable expuesto públicamente? La misma vulnerabilidad cambia radicalmente de riesgo según dónde se encuentre. No basta con conocer el CVE: hay que conocer dónde existe ese CVE.
  • KEV. ¿Está la vulnerabilidad en el catálogo Known Exploited Vulnerabilities? Si es así, desaparece gran parte de la incertidumbre: existe evidencia de explotación real.
  • Automatización del exploit. ¿Puede un atacante automatizar todas las etapas necesarias para explotarla, a escala y contra miles de sistemas? En el contexto de la IA, esta variable es cada vez más determinante.

KEV: saber que alguien ya está atacando cambia la prioridad

El informe dedica especial atención al catálogo Known Exploited Vulnerabilities. El KEV proporciona una de las señales más valiosas disponibles para cualquier proceso de priorización: evidencia de que la vulnerabilidad ya está siendo explotada en el mundo real.

Esto permite diferenciar dos situaciones completamente distintas. Priorizar automáticamente una vulnerabilidad únicamente porque tiene un CVSS superior puede significar ignorar información fundamental sobre el riesgo: otra con menor CVSS, pero presente en el KEV y sobre un activo expuesto a Internet, puede representar una amenaza mucho más inmediata.

El KEV convierte la incertidumbre en evidencia: alguien ya está explotando esa vulnerabilidad.
CISA establece una advertencia todavía más contundente: si una KEV está expuesta a Internet, debe remediarse inmediatamente e investigarse la posible existencia de indicadores de compromiso.

El efecto Mythos y CISA describen el mismo problema

En nuestro artículo sobre el efecto Mythos planteábamos una paradoja: cuanto mejores sean nuestras herramientas para encontrar vulnerabilidades, mayor será el número de vulnerabilidades que tendremos que gestionar.

CISA describe ahora el mismo problema desde la perspectiva operativa. La IA puede incrementar el volumen de vulnerabilidades divulgadas. Los atacantes pueden automatizar cada vez más su explotación. Los activos continúan expuestos. Las vulnerabilidades conocidas siguen sin corregirse. Pero la capacidad disponible para remediar sigue siendo limitada.

Un equipo de Sistemas no puede duplicar automáticamente su capacidad porque el número de CVE se haya duplicado. Una organización tampoco puede reiniciar continuamente servidores de producción, desplegar diariamente cientos de parches o interrumpir procesos críticos cada vez que aparece una nueva vulnerabilidad.

Por eso la nueva batalla no será únicamente por el tiempo de detección. Será por el tiempo de remediación de las vulnerabilidades que realmente importan.

Y seguimos manteniendo demasiada tecnología vulnerable expuesta

El informe ofrece además datos especialmente reveladores sobre las organizaciones de infraestructura crítica analizadas.

~26% exponía servicios de red vulnerables
~18% mantenía servidores FTP
51% usaba software sin soporte ligado a más de la mitad de las KEV
91% seguía con SSL/TLS obsoleto, sin corregir una mediana de 459 días

La conclusión vuelve a ser la misma. No siempre nos comprometen porque el atacante disponga de una técnica revolucionaria. Con frecuencia nos comprometen porque existe una vulnerabilidad conocida en un sistema que hemos dejado expuesto demasiado tiempo.

Aquí es donde el enfoque de vulloop coincide con CISA

Esta evolución hacia una gestión basada en riesgo es precisamente la filosofía sobre la que se ha construido vulloop. Ambos enfoques parten del mismo principio: una vulnerabilidad no debe priorizarse únicamente por su severidad técnica.

Para decidir qué remediar primero necesitamos contexto. vulloop correlaciona el inventario real de activos, productos, componentes y versiones de una organización con información de vulnerabilidades y señales de explotación. A partir de ahí incorpora factores como:

  • severidad técnica;
  • presencia en CISA KEV y EU KEV;
  • probabilidad de explotación;
  • existencia de exploits o señales de amenaza;
  • exposición del activo;
  • criticidad del activo;
  • proceso de negocio afectado;
  • alcance dentro del inventario;
  • disponibilidad de parche o mitigación.

El objetivo es transformar una lista de vulnerabilidades en una pregunta mucho más útil: ¿qué vulnerabilidades debemos corregir primero para reducir realmente nuestra exposición?

Inventario, contexto y trazabilidad

Hay además un requisito previo que a menudo se olvida. Para responder a la primera pregunta de CISA —¿está el activo expuesto?— primero debemos saber qué activos existen, qué software ejecutan, qué versiones tienen instaladas, dónde se encuentran, qué servicios prestan y qué importancia tienen para el negocio.

Sin un inventario fiable, la priorización basada en riesgo es prácticamente imposible. Por eso vulloop comienza precisamente por el inventario y correlaciona los CVE con aquello que realmente está desplegado en la organización, combinando inventario, correlación automática de CVE, priorización contextual y trazabilidad de las decisiones de remediación.

El objetivo no termina cuando se identifica la vulnerabilidad. Hay que poder demostrar qué se detectó, por qué se priorizó, quién debía actuar, qué acción se realizó, cuándo se ejecutó y qué riesgo permanece después de la remediación.

Ese paso es especialmente importante en un contexto en el que NIS2, DORA, ENS y CRA están elevando las exigencias de gestión, seguimiento y evidencia del riesgo de ciberseguridad.

La conclusión de CISA es también una advertencia

Durante años hemos intentado disponer de mejores escáneres, mejores fuentes de vulnerabilidades y mayor capacidad de detección. La Inteligencia Artificial puede acelerar todavía más esa tendencia. Pero encontrar más vulnerabilidades no significa automáticamente estar más seguros: podría producir el efecto contrario si el resultado son decenas de miles de alertas adicionales que los equipos no tienen capacidad para procesar.

El informe de CISA nos obliga por tanto a cambiar la pregunta. Ya no: ¿cuántas vulnerabilidades tenemos? Ni siquiera: ¿cuántas vulnerabilidades críticas tenemos? La pregunta que debería dirigir la gestión moderna de vulnerabilidades es: ¿qué vulnerabilidades representan ahora mismo mayor riesgo para nuestros activos y cuáles debemos remediar primero?

En nuestro artículo sobre el efecto Mythos concluíamos que, en la era de la IA, probablemente no ganará quien encuentre más vulnerabilidades. Después de revisar los datos de CISA, esa conclusión es todavía más válida: ganará quien pueda distinguir rápidamente cuáles importan, actuar antes sobre ellas y demostrar que realmente ha reducido su exposición.

Cuando las vulnerabilidades empiezan a descubrirse a velocidad de IA, priorizar deja de ser una mejora de la gestión de vulnerabilidades y se convierte en una necesidad operativa.

Prioriza por riesgo real, no solo por CVSS

vulloop correlaciona tu inventario con las señales de explotación y convierte miles de vulnerabilidades en una cola de remediación priorizada y trazable.

A few days ago we published the vulloop article "The Mythos effect: vulnerabilities discovered at AI speed, remediation at human speed".

The thesis was simple: artificial intelligence can start finding vulnerabilities much faster than organizations are able to analyze, prioritize, and remediate them.

The consequence matters. If vulnerability discovery begins to happen at machine scale while patching a server, testing a new release, approving a change, or coordinating a maintenance window still depends on human processes, the vulnerability management problem changes radically.

It is no longer only about finding vulnerabilities. It is about deciding which ones we need to fix first.

CISA has now added a particularly relevant argument to this thesis. In its new CISA Vulnerability Review, based on fiscal year 2024 and 2025 data, the U.S. Cybersecurity and Infrastructure Security Agency analyzes which vulnerabilities are generating real risk, how they are being exploited, and, above all, how they should be prioritized.

One of its conclusions is especially significant: "AI-enabled vulnerability discovery is rapidly increasing the volume of disclosed vulnerabilities, requiring much stricter patch prioritization."

CISA agrees with the shift driven by AI

One of the most interesting aspects of the report is how CISA positions its own data. The agency explains that it publishes this review to establish a baseline of the vulnerability landscape prior to the widespread adoption of AI-enabled vulnerability discovery.

It is not claiming that every new CVE is a consequence of artificial intelligence, nor that there is a direct causal link between a specific model and the current increase in vulnerabilities. But it is acknowledging a structural change: AI is altering the scale at which vulnerabilities can be discovered.

That is exactly what we called the Mythos effect in our previous article. And CISA adds the other side of the equation: attackers are also increasingly using AI to automate the steps required to exploit vulnerabilities.

Discovery is accelerating; the capacity to remediate production services is not.

CISA: CVSS is no longer enough

For years, a large part of vulnerability management has relied on a relatively simple logic: Critical → High → Medium → Low.

The problem is that this classification fundamentally answers one question: what is the technical severity of this vulnerability? It does not necessarily answer the question that actually matters to an organization: which one do I fix first?

CISA is especially clear on this point. According to the report, using CVSS as the primary decision metric is insufficient because CVSS reflects theoretical severity, not necessarily real-world impact.

Lower operational priority CVSS 9.8
  • No known exploitation
  • Internal, isolated server
  • Protected by several network controls

Can be planned

Top priority CVSS 7.8
  • In the KEV catalog: active exploitation
  • Directly exposed to the internet
  • Exploitation easily automatable
  • Enables control of a critical system

Immediate remediation

CVSS remains relevant information, but it stops being the decision.

The questions CISA proposes asking

To prioritize vulnerabilities, CISA proposes focusing the decision on a small set of variables.

  • Asset exposure. Is the vulnerable asset publicly exposed? The same vulnerability changes risk radically depending on where it lives. Knowing the CVE is not enough: you need to know where that CVE exists.
  • KEV. Is the vulnerability in the Known Exploited Vulnerabilities catalog? If so, much of the uncertainty disappears: there is evidence of real-world exploitation.
  • Exploit automation. Can an attacker automate every step required to exploit it, at scale and against thousands of systems? In the context of AI, this variable is increasingly decisive.

KEV: knowing someone is already attacking changes the priority

The report pays particular attention to the Known Exploited Vulnerabilities catalog. KEV provides one of the most valuable signals available for any prioritization process: evidence that the vulnerability is already being exploited in the real world.

This makes it possible to tell apart two completely different situations. Automatically prioritizing a vulnerability just because it has a higher CVSS score can mean ignoring fundamental risk information: another one with a lower CVSS score, but listed in KEV and on an internet-facing asset, may represent a far more immediate threat.

KEV turns uncertainty into evidence: someone is already exploiting that vulnerability.
CISA issues an even blunter warning: if a KEV is exposed to the internet, it must be remediated immediately and possible indicators of compromise must be investigated.

The Mythos effect and CISA describe the same problem

In our Mythos effect article we raised a paradox: the better our tools become at finding vulnerabilities, the more vulnerabilities we will have to manage.

CISA now describes the same problem from the operational side. AI can increase the volume of disclosed vulnerabilities. Attackers can increasingly automate their exploitation. Assets remain exposed. Known vulnerabilities remain unpatched. But the available capacity to remediate stays limited.

An IT team cannot automatically double its capacity because the number of CVEs has doubled. Nor can an organization continuously reboot production servers, deploy hundreds of patches every day, or interrupt critical processes every time a new vulnerability appears.

That is why the new battle will not be only about detection time. It will be about the remediation time of the vulnerabilities that actually matter.

And we still keep too much vulnerable technology exposed

The report also offers particularly revealing data about the critical infrastructure organizations analyzed.

~26% exposed vulnerable network services
~18% kept FTP servers running
51% used unsupported software tied to more than half of all KEVs
91% still ran obsolete SSL/TLS, unfixed for a median of 459 days

The conclusion is the same again. We are not always compromised because the attacker has a revolutionary technique. We are frequently compromised because a known vulnerability exists in a system we have left exposed for too long.

This is where vulloop's approach meets CISA

This evolution toward risk-based management is precisely the philosophy vulloop is built on. Both approaches start from the same principle: a vulnerability should not be prioritized on technical severity alone.

To decide what to remediate first, we need context. vulloop correlates an organization's actual inventory of assets, products, components, and versions with vulnerability information and exploitation signals. From there it incorporates factors such as:

  • technical severity;
  • presence in CISA KEV and EU KEV;
  • probability of exploitation;
  • existence of exploits or threat signals;
  • asset exposure;
  • asset criticality;
  • affected business process;
  • scope across the inventory;
  • availability of a patch or mitigation.

The goal is to turn a list of vulnerabilities into a much more useful question: which vulnerabilities should we fix first to genuinely reduce our exposure?

Inventory, context, and traceability

There is also a prerequisite that is often forgotten. To answer CISA's first question —is the asset exposed?— we first need to know which assets exist, what software they run, which versions are installed, where they are, what services they provide, and how important they are to the business.

Without a reliable inventory, risk-based prioritization is practically impossible. That is why vulloop starts precisely with the inventory and correlates CVEs with what is actually deployed in the organization, combining inventory, automatic CVE correlation, contextual prioritization, and traceability of remediation decisions.

The goal does not end when the vulnerability is identified. You have to be able to demonstrate what was detected, why it was prioritized, who was responsible, what action was taken, when it was executed, and what risk remains after remediation.

That step is especially important in a context where NIS2, DORA, ENS, and CRA are raising the requirements for managing, tracking, and evidencing cybersecurity risk.

CISA's conclusion is also a warning

For years we have tried to have better scanners, better vulnerability sources, and greater detection capacity. Artificial intelligence can accelerate that trend even further. But finding more vulnerabilities does not automatically mean being more secure: it could produce the opposite effect if the result is tens of thousands of additional alerts that teams have no capacity to process.

The CISA report therefore forces us to change the question. No longer: how many vulnerabilities do we have? Not even: how many critical vulnerabilities do we have? The question that should drive modern vulnerability management is: which vulnerabilities pose the greatest risk to our assets right now, and which ones should we remediate first?

In our Mythos effect article we concluded that, in the age of AI, the winner will probably not be whoever finds the most vulnerabilities. After reviewing CISA's data, that conclusion is even stronger: the winner will be whoever can quickly tell which ones matter, act on them sooner, and demonstrate a genuine reduction in exposure.

When vulnerabilities start being discovered at AI speed, prioritization stops being an improvement to vulnerability management and becomes an operational necessity.

Prioritize by real risk, not just CVSS

vulloop correlates your inventory with exploitation signals and turns thousands of vulnerabilities into a prioritized, traceable remediation queue.